Subprocessors draft

Current and optional service providers

This launch draft lists the infrastructure and service providers Yrka expects to use to operate the hosted product. Optional providers apply only when the related feature or environment is configured.

Supabase - configured

Purpose: Authentication, database, and private file storage.

Data involved: Account, user, organization, workforce, document metadata, and uploaded file data.

Vercel - configured

Purpose: Application hosting, deployment, runtime logs, and public-site analytics when enabled.

Data involved: Application traffic, runtime metadata, logs, and aggregate analytics events.

Stripe - configured

Purpose: Billing, subscription lifecycle, invoices, and payment method handling.

Data involved: Billing contacts, Stripe customer/subscription metadata, invoice/payment lifecycle data.

Sentry - optional

Purpose: Application error monitoring and diagnostics.

Data involved: Error traces, environment metadata, route context, and diagnostic logs when configured.

Resend - optional

Purpose: Outbound transactional email.

Data involved: Email addresses, message content, and delivery metadata when configured.

Google Workspace APIs - optional

Purpose: Google sign-in diagnostics and optional Google Calendar or Drive reviewed sync when a customer authorizes the provider connection.

Data involved: Verified identity profile, selected calendar/file metadata, staged event or source content, sync cursors, and provider delivery metadata. OAuth tokens remain server-only.

Microsoft Graph - optional

Purpose: Microsoft sign-in diagnostics and optional Microsoft Calendar or SharePoint/OneDrive reviewed sync when a customer authorizes the provider connection.

Data involved: Verified identity profile, selected calendar/site/file metadata, staged event or source content, delta cursors, and provider delivery metadata. OAuth tokens remain server-only.

Notion - optional

Purpose: Optional reviewed source sync for selected Notion pages when a customer authorizes the provider connection.

Data involved: Selected page metadata/content staged for Resources review, page version evidence, sync cursors, and provider account display metadata. OAuth tokens remain server-only.

Slack - optional

Purpose: Optional Slack webhook notification delivery and Slack app OAuth outbound notification delivery when a customer authorizes the app and configures a channel. Interactive approvals, slash commands, and two-way workflows remain out of launch scope.

Data involved: Redacted notification summary text, deep links, destination metadata, and delivery status when configured.

Twilio - optional

Purpose: Optional SMS notification delivery when server-side SMS settings are configured.

Data involved: Recipient phone number, redacted notification summary text, deep links, and delivery status when configured.

Browser push services - optional

Purpose: Web Push transport for users who enable supported browser or installable PWA notifications.

Data involved: Encrypted notification payloads, push endpoints, and delivery metadata handled by the user browser/device push service.

Google Analytics - optional

Purpose: Optional public marketing-site analytics after first-party visitor consent.

Data involved: Public marketing page events, device/browser metadata, and approximate traffic measurement data.

Google AI / configured AI providers - optional

Purpose: AI-assisted resource lookup, summaries, and admin/employee assistant features.

Data involved: Prompt content and selected context when AI features are enabled.

Yrka uses optional analytics on the public site to understand page interest. The authenticated app does not load GA4.